First published: Tue Mar 15 2022(Updated: )
IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access | <=10.0.0, 10.0.1, 10.0.2, 10.0.3 | |
IBM Security Verify Access | =10.0.0 | |
IBM Security Verify Access | =10.0.1 | |
IBM Security Verify Access | =10.0.2 | |
IBM Security Verify Access | =10.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue is CVE-2022-22311.
The severity level of CVE-2022-22311 is medium, with a severity value of 6.5.
IBM Security Verify Access versions 10.0.0, 10.0.1, 10.0.2, and 10.0.3 are affected by CVE-2022-22311.
This vulnerability can be exploited by a user using man in the middle techniques to obtain sensitive information or possibly change some information due to improper validation of JWT tokens.
To fix CVE-2022-22311, it is recommended to update IBM Security Verify Access to a version that is not affected by the vulnerability.